Rookits: Win32/Sirefef.AB, Win64/Sirefef.P - Google Redirect [Solved]
11 min read
Plug the flashdrive into the infected PC.
Restart your computer and tap F8 to bring up the Advanced Menu, then click Repair your computer
Follow the prompt to enter keyboard input method, and then the prompt to enter a password. If the machine does not have a password, simply click Enter.
In the next menu, use the arrow keys on the keyboard to highlight Command Prompt and press Enter.
- In the command window type in notepad and press Enter.
- The notepad opens. Under File menu select Open.
- Select "Computer" and find your flash drive letter and close the notepad.
- In the command window type e:\frst.exe and press Enter.
- The tool will start to run.
- When the tool opens click Yes to disclaimer.
- Uncheck the Whitlelist boxes next to Registry, Services, Drivers, known DLL's, and List Drivers MD5
- Press Scan button.
- It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.
Enter g:\frst64.exe instead. Sorry about that.
Sorry about that, you need the 64 bit executable. Download and save FRST64.exe to your flash drive and repeat the above steps.
C:\Users\Andrew\AppData\Roaming\googleoez.exe
2012-05-19 15:00 - 2011-10-03 22:07 - 0000340 ____A C:\Windows\Tasks\At11.job
2012-05-19 14:00 - 2011-10-03 22:07 - 0000340 ____A C:\Windows\Tasks\At10.job
2012-05-19 13:00 - 2011-10-03 22:07 - 0000340 ____A C:\Windows\Tasks\At9.job
2012-05-19 12:00 - 2011-10-03 22:07 - 0000340 ____A C:\Windows\Tasks\At8.job
2012-05-19 11:00 - 2011-10-03 22:07 - 0000340 ____A C:\Windows\Tasks\At7.job
2012-05-19 10:00 - 2011-10-03 22:07 - 0000340 ____A C:\Windows\Tasks\At6.job
2012-05-19 09:00 - 2011-10-03 22:07 - 0000340 ____A C:\Windows\Tasks\At5.job
2012-05-19 08:00 - 2011-10-03 22:07 - 0000340 ____A C:\Windows\Tasks\At4.job
2012-05-19 07:00 - 2011-10-03 22:07 - 0000340 ____A C:\Windows\Tasks\At3.job
2012-05-19 06:19 - 2011-10-03 22:07 - 0000340 ____A C:\Windows\Tasks\At2.job
2012-05-19 05:00 - 2011-10-03 22:08 - 0000340 ____A C:\Windows\Tasks\At25.job
2012-05-19 04:00 - 2011-10-03 22:08 - 0000340 ____A C:\Windows\Tasks\At24.job
2012-05-19 03:00 - 2011-10-03 22:08 - 0000340 ____A C:\Windows\Tasks\At23.job
2012-05-19 02:00 - 2011-10-03 22:08 - 0000340 ____A C:\Windows\Tasks\At22.job
2012-05-19 01:00 - 2011-10-03 22:07 - 0000340 ____A C:\Windows\Tasks\At21.job
2012-05-19 00:00 - 2011-10-03 22:07 - 0000340 ____A C:\Windows\Tasks\At20.job
2012-05-18 23:00 - 2011-10-03 22:07 - 0000340 ____A C:\Windows\Tasks\At19.job
2012-05-18 22:00 - 2011-10-03 22:07 - 0000340 ____A C:\Windows\Tasks\At18.job
2012-05-18 21:00 - 2011-10-03 22:07 - 0000340 ____A C:\Windows\Tasks\At17.job
2012-05-18 20:00 - 2011-10-03 22:07 - 0000340 ____A C:\Windows\Tasks\At16.job
2012-05-18 19:00 - 2011-10-03 22:07 - 0000340 ____A C:\Windows\Tasks\At15.job
2012-05-18 18:00 - 2011-10-03 22:07 - 0000340 ____A C:\Windows\Tasks\At14.job
2012-05-18 17:00 - 2011-10-03 22:07 - 0000340 ____A C:\Windows\Tasks\At13.job
Restart your computer and tap F8 to bring up the Advanced Menu, then click Repair your computer
Follow the prompt to enter keyboard input method, and then the prompt to enter a password. If the machine does not have a password, simply click Enter.
In the next menu, use the arrow keys on the keyboard to highlight Command Prompt and press Enter.
g:\frst64.exe
When the tool opens, click the Fix button just once, then wait. A log will be produced on the flash drive named Fix.txt
==================================
Restart the machine and disable your AV. Try again to run ComboFix.exe.
If it still won't run, then please post the log produce by AntiZeroAccess tool that you ran a couple days ago. It would be in the same location as where you ran that tool from.
Forget what I said about the AntiZeroAccess log for now. I need you to download Hitman Pro 64-bit.
Please run a scan with it and take a screenshot of the results. DO NOT try to remove what it finds. Hitman Pro will only remove the rootkit if you buy the software and even then, it is not capable of completely removing ZeroAccess.
[external image: Posted Image]
[external image: Posted Image]
If you have a problem with reading the text, due to the black background and the text, let me know and I'll fix it up.
Also I've noticed that there are several PING.EXE processes under taskmanager, obviously part of this virus/rootkit/trojan but it is starting to clog up my PC.
Okay Hitman is not showing what I need to see either. This is a new and stubborn variant of ZeroAccess. I need you to delete ComboFix from your desktop and download the updated version from the link below:
Link 1
Try running ComboFix again.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI